Vulnerability index

Browse CVEs

360 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

R Seenet MEDIUM 6.5
CVE-2021-21928

A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at ‘mac_filter’ parameter to trigger thi…

No fix yet
Fix from $1,600 2021-12-22
R Seenet MEDIUM 6.5
CVE-2021-21929

A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at ‘prod_filter’ parameter to trigger th…

No fix yet
Fix from $1,600 2021-12-22
R Seenet MEDIUM 6.5
CVE-2021-21930

A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at ‘sn_filter’ parameter to trigger this…

No fix yet
Fix from $1,600 2021-12-22
R Seenet MEDIUM 6.5
CVE-2021-21931

A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at‘ stat_filter’ parameter to trigger th…

No fix yet
Fix from $1,600 2021-12-22
R Seenet MEDIUM 6.5
CVE-2021-21932

A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this at ‘name_filter’ paramet…

No fix yet
Fix from $1,600 2021-12-22
R Seenet MEDIUM 6.5
CVE-2021-21933

A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this at ‘esn_filter’ paramete…

No fix yet
Fix from $1,600 2021-12-22
R Seenet MEDIUM 6.5
CVE-2021-21934

A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this at ‘imei_filter’ paramet…

No fix yet
Fix from $1,600 2021-12-22
R Seenet MEDIUM 6.5
CVE-2021-21935

A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘host_a…

No fix yet
Fix from $1,600 2021-12-22
R Seenet HIGH 7.8
CVE-2021-21910

A privilege escalation vulnerability exists in the Windows version of installation for Advantech R-SeeNet Advantech R-SeeNet 2.4.15 (30.07.2021). A s…

No fix yet
Fix from $1,950 2021-12-22
Webaccess Hmi Designer MEDIUM 6.1
CVE-2021-42703

This vulnerability could allow an attacker to send malicious Javascript code resulting in hijacking of the user’s cookie/session tokens, redirecting …

Fix: 2.1.11.0+
Fix from $1,600 2021-11-15
Webaccess Hmi Designer HIGH 7.8
CVE-2021-42706

This vulnerability could allow an attacker to disclose information and execute arbitrary code on affected installations of WebAccess/MHI Designer

Fix: 2.1.11.0+
Fix from $1,950 2021-11-15
Webaccess\/nms MEDIUM 5.3
CVE-2021-32951

WebAccess/NMS (Versions prior to v3.0.3_Build6299) has an improper authentication vulnerability, which may allow unauthorized users to view resources…

Fix: after 3.0.3
Fix from $1,600 2021-10-27
Webaccess CRITICAL 9.8
CVE-2021-33023

Advantech WebAccess versions 9.02 and prior are vulnerable to a heap-based buffer overflow, which may allow an attacker to remotely execute code.

Fix: after 9.0.2
Fix from $2,300 2021-10-18
Webaccess CRITICAL 9.8
CVE-2021-38389EPSS 10%

Advantech WebAccess versions 9.02 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute code.

Fix: after 9.0.2
Fix from $2,300 2021-10-18
Webaccess CRITICAL 9.8
CVE-2021-38408EPSS 12%

A stack-based buffer overflow vulnerability in Advantech WebAccess Versions 9.02 and prior caused by a lack of proper validation of the length of use…

Fix: after 9.02
Fix from $2,300 2021-09-09
Webaccess\/scada CRITICAL 9.8
CVE-2021-32943

The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code on the WebAccess/…

Fix: 8.4.5 / 9.0.1+
Fix from $2,300 2021-08-10
Webaccess\/scada MEDIUM 6.1
CVE-2021-22676

UserExcelOut.asp within WebAccess/SCADA is vulnerable to cross-site scripting (XSS), which could allow an attacker to send malicious JavaScript code.…

Fix: 8.4.5 / 9.0.1+
Fix from $1,600 2021-08-10
Webaccess\/scada MEDIUM 6.5
CVE-2021-22674

The affected product is vulnerable to a relative path traversal condition, which may allow an attacker access to unauthorized files and directories o…

Fix: 8.4.5 / 9.0.1+
Fix from $1,600 2021-08-10
R Seenet CRITICAL 9.8
CVE-2021-21805EPSS 70%

An OS Command Injection vulnerability exists in the ping.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). A specially crafted HT…

No fix yet
Fix from $2,300 2021-08-05
R Seenet CRITICAL 9.8
CVE-2021-21804

A local file inclusion (LFI) vulnerability exists in the options.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). A specially cr…

No fix yet
Fix from $2,300 2021-07-16
R Seenet MEDIUM 6.1
CVE-2021-21799EPSS 12%

Cross-site scripting vulnerabilities exist in the telnet_form.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). If a user visits …

No fix yet
Fix from $1,600 2021-07-16
R Seenet MEDIUM 6.1
CVE-2021-21800EPSS 14%

Cross-site scripting vulnerabilities exist in the ssh_form.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). If a user visits a s…

No fix yet
Fix from $1,600 2021-07-16
R Seenet MEDIUM 6.1
CVE-2021-21801EPSS 63%

This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by…

No fix yet
Fix from $1,600 2021-07-16
R Seenet MEDIUM 6.1
CVE-2021-21802EPSS 10%

This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by…

No fix yet
Fix from $1,600 2021-07-16
R Seenet MEDIUM 6.1
CVE-2021-21803EPSS 8%

This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by…

No fix yet
Fix from $1,600 2021-07-16
Webaccess\/hmi Designer HIGH 7.8
CVE-2021-33000

Parsing a maliciously crafted project file may cause a heap-based buffer overflow, which may allow an attacker to perform arbitrary code execution. U…

Fix: after 2.1.9.95
Fix from $1,950 2021-06-24
Webaccess\/hmi Designer HIGH 7.8
CVE-2021-33002

Opening a maliciously crafted project file may cause an out-of-bounds write, which may allow an attacker to execute arbitrary code. User interaction …

Fix: after 2.1.9.95
Fix from $1,950 2021-06-24
Webaccess\/hmi Designer HIGH 7.8
CVE-2021-33004

The affected product is vulnerable to memory corruption condition due to lack of proper validation of user supplied files, which may allow an attacke…

Fix: after 2.1.9.95
Fix from $1,950 2021-06-24
Webaccess\/scada MEDIUM 6.5
CVE-2021-32954

Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to a directory traversal, which may allow an attacker to remotely read arbitrary fil…

Fix: after 9.0.1
Fix from $1,600 2021-06-18
Webaccess\/scada MEDIUM 6.1
CVE-2021-32956

Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to redirection, which may allow an attacker to send a maliciously crafted URL that c…

Fix: after 9.0.1
Fix from $1,600 2021-06-18